USERINIT.exe nakažen Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

USERINIT.exe nakažen

Příspěvekod autoprd » 13 zář 2012 19:37

Ahoj sestra si stěžovala že má malo místa na cčku a je zaekanej pc tak sem jí projel hijack, mwaw, CF a tam se mi objevilo
System file is infected attempting to restore C:\Windows\system32\userinit.exe nějak tak ;) Jakpa na to děkuju


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:55:31, on 13.9.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Get Styles\enlbrdr.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm
O9 - Extra 'Tools' menuitem: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Guard.Mail.ru - Unknown owner - C:\Program Files\Guard-ICQ\GuardICQ.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: ICQ Service - Unknown owner - C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Unknown owner - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Unknown owner - C:\Program Files\Skype\Updater\Updater.exe (file missing)

--
End of file - 6023 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: USERINIT.exe nakažen

Příspěvekod jaro3 » 13 zář 2012 20:23

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')


Stáhni si ATF Cleaner
Poklepej na ATF Cleaner.exe, klikni na select all found, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.


Stáhni si TFC
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni si Malwarebytes' Anti-Malware
Nainstaluj a spusť ho
- na konci instalace se ujisti že máš zvoleny/zatrhnuty obě možnosti:
Aktualizace Malwarebytes' Anti-Malware a Spustit aplikaci Malwarebytes' Anti-Malware, pokud jo tak klikni na tlačítko konec
- pokud bude nalezena aktualizace, tak se stáhne a nainstaluje
- program se po té spustí a nech vybranou možnost Provést rychlý sken a klikni na tlačítko Skenovat
- po proběhnutí programu se ti objeví hláška tak klikni na OK a pak na tlačítko Zobrazit výsledky
- pak zvol možnost uložit log a ulož si log na plochu
- po té klikni na tlačítko Exit, objeví se ti hláška tak zvol Ano
(zatím nic nemaž!).
Vlož sem pak obsah toho logu.

Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 13 zář 2012 20:37

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Verze databáze: v2012.09.13.09

Windows 7 x86 NTFS
Internet Explorer 9.0.8112.16421
Luciasheq :: LUCIASHEQ-PC [administrátor]

13.9.2012 20:32:45
mbam-log-2012-09-13 (20-37-40).txt

Typ: Rychlá kontrola
Nastavení kontroly povoleno: Paměť | Po spuštění | Registr | Systémové soubory | Heuristická analýza Extra | Heuristická analýza Shuriken | PUP | PUM
Nastavení kontroly zakázáno: P2P
Kontrolované objekty: 190117
Uplynulý čas: 4 minut, 45 sekund

Nalezené procesy v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené moduly v paměti: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené klíče v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené hodnoty v registru: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené datové položky v registru: 1
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit (Hijack.UserInit) -> Špatný: (C:\Windows\explorer.exe,) Dobrý: (userinit.exe) -> Žádná instrukce nebyla provedena.

Nalezené složky: 0
(Žádné škodlivé položky nebyly zjištěny)

Nalezené soubory: 0
(Žádné škodlivé položky nebyly zjištěny)

(konec)

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: USERINIT.exe nakažen

Příspěvekod memphisto » 14 zář 2012 11:08

Vše z Mbam smaž

Stáhni si TDSSKiller
Na svojí plochu.Ujisti se , že máš zavřeny všechny ostatní aplikace a prohlížeče. Rozbal soubor a spusť TDSSKiller.exe. Restartuj PC . Log z TDSSKilleru najdeš zde:
C:\TDSSKiller.2.2.7.1._(datum)_log.txt , vlož sem prosím celý obsah logu.

Vypni rezidentní štít antiviru a antispywaru
Stáhni si ComboFix (by sUBs)
a ulož si ho na plochu.
Ukonči všechna aktivní okna a spusť ho.
- Po spuštění se zobrazí podmínky užití, potvrď je stiskem tlačítka Ano
- Dále postupuj dle pokynů, během aplikování ComboFixu neklikej do zobrazujícího se okna
- Po dokončení skenování by měl program vytvořit log - C:\ComboFix.txt - zkopíruj sem prosím celý jeho obsah
Pokud bude po kontrole problém spustit aplikace nebo bude vyskakovat hláška o pokusu použít neplatnou operaci na klíč registru, který je označen pro odstranění, stačí restartovat počítač.
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 14 zář 2012 15:18

15:16:29.0488 0940 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
15:16:29.0573 0940 ============================================================
15:16:29.0573 0940 Current date / time: 2012/09/14 15:16:29.0573
15:16:29.0573 0940 SystemInfo:
15:16:29.0573 0940
15:16:29.0573 0940 OS Version: 6.1.7600 ServicePack: 0.0
15:16:29.0573 0940 Product type: Workstation
15:16:29.0574 0940 ComputerName: LUCIASHEQ-PC
15:16:29.0574 0940 UserName: Luciasheq
15:16:29.0574 0940 Windows directory: C:\Windows
15:16:29.0574 0940 System windows directory: C:\Windows
15:16:29.0574 0940 Processor architecture: Intel x86
15:16:29.0574 0940 Number of processors: 2
15:16:29.0574 0940 Page size: 0x1000
15:16:29.0574 0940 Boot type: Normal boot
15:16:29.0574 0940 ============================================================
15:16:31.0333 0940 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
15:16:31.0340 0940 ============================================================
15:16:31.0340 0940 \Device\Harddisk0\DR0:
15:16:31.0344 0940 MBR partitions:
15:16:31.0344 0940 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1ADB3A90
15:16:31.0344 0940 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1ADB3AD5, BlocksNum 0x1F5D116C
15:16:31.0344 0940 ============================================================
15:16:31.0395 0940 C: <-> \Device\Harddisk0\DR0\Partition1
15:16:31.0441 0940 D: <-> \Device\Harddisk0\DR0\Partition2
15:16:31.0441 0940 ============================================================
15:16:31.0441 0940 Initialize success
15:16:31.0442 0940 ============================================================
15:16:33.0343 6124 ============================================================
15:16:33.0343 6124 Scan started
15:16:33.0343 6124 Mode: Manual;
15:16:33.0343 6124 ============================================================
15:16:34.0218 6124 ================ Scan system memory ========================
15:16:34.0218 6124 System memory - ok
15:16:34.0219 6124 ================ Scan services =============================
15:16:34.0393 6124 [ 6D2ACA41739BFE8CB86EE8E85F29697D ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
15:16:34.0395 6124 1394ohci - ok
15:16:34.0422 6124 [ F0E07D144C8685B8774BC32FC8DA4DF0 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
15:16:34.0426 6124 ACPI - ok
15:16:34.0448 6124 [ 98D81CA942D19F7D9153B095162AC013 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
15:16:34.0449 6124 AcpiPmi - ok
15:16:34.0465 6124 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
15:16:34.0471 6124 adp94xx - ok
15:16:34.0498 6124 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
15:16:34.0521 6124 adpahci - ok
15:16:34.0530 6124 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
15:16:34.0532 6124 adpu320 - ok
15:16:34.0704 6124 [ E690647AE0B4111E3D82FCE27FDFD9B4 ] AdvancedSystemCareService5 C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
15:16:34.0711 6124 AdvancedSystemCareService5 - ok
15:16:34.0746 6124 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
15:16:34.0747 6124 AeLookupSvc - ok
15:16:34.0780 6124 [ 0DB7A48388D54D154EBEC120461A0FCD ] AFD C:\Windows\system32\drivers\afd.sys
15:16:34.0786 6124 AFD - ok
15:16:34.0840 6124 [ 6416F9B6B220F0A890525C38235AFAD7 ] AgereModemAudio C:\Program Files\LSI SoftModem\agrsmsvc.exe
15:16:34.0842 6124 AgereModemAudio - ok
15:16:34.0936 6124 [ BCEB020D36634CADA07882E4C221E85E ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
15:16:34.0950 6124 AgereSoftModem - ok
15:16:34.0989 6124 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
15:16:34.0991 6124 agp440 - ok
15:16:35.0019 6124 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
15:16:35.0021 6124 aic78xx - ok
15:16:35.0074 6124 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
15:16:35.0075 6124 ALG - ok
15:16:35.0097 6124 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
15:16:35.0098 6124 aliide - ok
15:16:35.0150 6124 [ 4FCA011A5AFB252CAB7B30EF12A99CE8 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
15:16:35.0153 6124 AMD External Events Utility - ok
15:16:35.0183 6124 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
15:16:35.0185 6124 amdagp - ok
15:16:35.0198 6124 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
15:16:35.0199 6124 amdide - ok
15:16:35.0214 6124 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
15:16:35.0216 6124 AmdK8 - ok
15:16:35.0229 6124 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
15:16:35.0231 6124 AmdPPM - ok
15:16:35.0264 6124 [ 19CE906B4CDC11FC4FEF5745F33A63B6 ] amdsata C:\Windows\system32\drivers\amdsata.sys
15:16:35.0266 6124 amdsata - ok
15:16:35.0280 6124 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
15:16:35.0282 6124 amdsbs - ok
15:16:35.0294 6124 [ 869E67D66BE326A5A9159FBA8746FA70 ] amdxata C:\Windows\system32\drivers\amdxata.sys
15:16:35.0295 6124 amdxata - ok
15:16:35.0319 6124 [ 91B05BBB609C79D73E2332B6E5F99AEA ] ApfiltrService C:\Windows\system32\DRIVERS\Apfiltr.sys
15:16:35.0322 6124 ApfiltrService - ok
15:16:35.0363 6124 [ FEB834C02CE1E84B6A38F953CA067706 ] AppID C:\Windows\system32\drivers\appid.sys
15:16:35.0365 6124 AppID - ok
15:16:35.0415 6124 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
15:16:35.0417 6124 AppIDSvc - ok
15:16:35.0430 6124 [ 7DEAD9E3F65DCB2794F2711003BBF650 ] Appinfo C:\Windows\System32\appinfo.dll
15:16:35.0432 6124 Appinfo - ok
15:16:35.0524 6124 [ 7EF47644B74EBE721CC32211D3C35E76 ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:16:35.0527 6124 Apple Mobile Device - ok
15:16:35.0558 6124 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
15:16:35.0562 6124 AppMgmt - ok
15:16:35.0592 6124 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
15:16:35.0595 6124 arc - ok
15:16:35.0610 6124 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
15:16:35.0614 6124 arcsas - ok
15:16:35.0666 6124 [ 054DF24C92B55427E0757CFFF160E4F2 ] aswFsBlk C:\Windows\system32\drivers\aswFsBlk.sys
15:16:35.0667 6124 aswFsBlk - ok
15:16:35.0745 6124 [ 258143605E77E4008F1758481D6A977D ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
15:16:35.0756 6124 aswMonFlt - ok
15:16:35.0829 6124 [ 352D5A48EBAB35A7693B048679304831 ] aswRdr C:\Windows\system32\drivers\aswRdr.sys
15:16:35.0867 6124 aswRdr - ok
15:16:35.0900 6124 [ 8D34D2B24297E27D93E847319ABFDEC4 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
15:16:35.0905 6124 aswSnx - ok
15:16:35.0928 6124 [ 010012597333DA1F46C3243F33F8409E ] aswSP C:\Windows\system32\drivers\aswSP.sys
15:16:35.0932 6124 aswSP - ok
15:16:35.0948 6124 [ F9F84364416658E9786235904D448D37 ] aswTdi C:\Windows\system32\drivers\aswTdi.sys
15:16:35.0949 6124 aswTdi - ok
15:16:35.0975 6124 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
15:16:35.0977 6124 AsyncMac - ok
15:16:36.0008 6124 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\DRIVERS\atapi.sys
15:16:36.0009 6124 atapi - ok
15:16:36.0117 6124 [ 274C792DBE80437452F6FC110E4DA742 ] athr C:\Windows\system32\DRIVERS\athr.sys
15:16:36.0187 6124 athr - ok
15:16:36.0579 6124 [ B0AD0B3ED60D9C60B85731A9E08E27B9 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
15:16:36.0690 6124 atikmdag - ok
15:16:36.0738 6124 [ 510C873BFA135AA829F4180352772734 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
15:16:36.0744 6124 AudioEndpointBuilder - ok
15:16:36.0759 6124 [ 510C873BFA135AA829F4180352772734 ] Audiosrv C:\Windows\System32\Audiosrv.dll
15:16:36.0763 6124 Audiosrv - ok
15:16:36.0817 6124 [ 996E6D052438E8D8DFD501F31560B2E0 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
15:16:36.0818 6124 avast! Antivirus - ok
15:16:36.0861 6124 [ DD6A431B43E34B91A767D1CE33728175 ] AxInstSV C:\Windows\System32\AxInstSV.dll
15:16:36.0863 6124 AxInstSV - ok
15:16:36.0914 6124 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
15:16:36.0918 6124 b06bdrv - ok
15:16:36.0949 6124 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
15:16:36.0952 6124 b57nd60x - ok
15:16:36.0991 6124 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
15:16:36.0993 6124 BDESVC - ok
15:16:37.0019 6124 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
15:16:37.0020 6124 Beep - ok
15:16:37.0053 6124 [ 85AC71C045CEB054ED48A7841AAE0C11 ] BFE C:\Windows\System32\bfe.dll
15:16:37.0059 6124 BFE - ok
15:16:37.0103 6124 [ 53F476476F55A27F580661BDE09C4EC4 ] BITS C:\Windows\system32\qmgr.dll
15:16:37.0113 6124 BITS - ok
15:16:37.0129 6124 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
15:16:37.0131 6124 blbdrive - ok
15:16:37.0211 6124 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
15:16:37.0216 6124 Bonjour Service - ok
15:16:37.0256 6124 [ 9A5C671B7FBAE4865149BB11F59B91B2 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
15:16:37.0257 6124 bowser - ok
15:16:37.0283 6124 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
15:16:37.0284 6124 BrFiltLo - ok
15:16:37.0294 6124 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
15:16:37.0295 6124 BrFiltUp - ok
15:16:37.0322 6124 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
15:16:37.0323 6124 BridgeMP - ok
15:16:37.0352 6124 [ A0E691DC6589D4D2CBE373171D1A49E5 ] Browser C:\Windows\System32\browser.dll
15:16:37.0354 6124 Browser - ok
15:16:37.0374 6124 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
15:16:37.0377 6124 Brserid - ok
15:16:37.0397 6124 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
15:16:37.0398 6124 BrSerWdm - ok
15:16:37.0407 6124 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
15:16:37.0408 6124 BrUsbMdm - ok
15:16:37.0415 6124 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
15:16:37.0417 6124 BrUsbSer - ok
15:16:37.0462 6124 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
15:16:37.0463 6124 BthEnum - ok
15:16:37.0480 6124 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
15:16:37.0481 6124 BTHMODEM - ok
15:16:37.0510 6124 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
15:16:37.0511 6124 BthPan - ok
15:16:37.0539 6124 [ 04CEDA17A195924070B01174CB1F9AF8 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
15:16:37.0543 6124 BTHPORT - ok
15:16:37.0580 6124 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
15:16:37.0582 6124 bthserv - ok
15:16:37.0604 6124 [ 80E6384BEEC03B8BD45EDEA29802D657 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
15:16:37.0605 6124 BTHUSB - ok
15:16:37.0709 6124 catchme - ok
15:16:37.0723 6124 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
15:16:37.0724 6124 cdfs - ok
15:16:37.0763 6124 [ BA6E70AA0E6091BC39DE29477D866A77 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
15:16:37.0765 6124 cdrom - ok
15:16:37.0806 6124 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] CertPropSvc C:\Windows\System32\certprop.dll
15:16:37.0808 6124 CertPropSvc - ok
15:16:37.0824 6124 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
15:16:37.0825 6124 circlass - ok
15:16:37.0848 6124 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
15:16:37.0851 6124 CLFS - ok
15:16:37.0934 6124 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:16:37.0936 6124 clr_optimization_v2.0.50727_32 - ok
15:16:37.0999 6124 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
15:16:38.0001 6124 clr_optimization_v4.0.30319_32 - ok
15:16:38.0018 6124 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
15:16:38.0019 6124 CmBatt - ok
15:16:38.0034 6124 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
15:16:38.0035 6124 cmdide - ok
15:16:38.0068 6124 [ DB5E008B3744DD60C8498CBBF2A1CFA6 ] CNG C:\Windows\system32\Drivers\cng.sys
15:16:38.0071 6124 CNG - ok
15:16:38.0091 6124 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
15:16:38.0092 6124 Compbatt - ok
15:16:38.0133 6124 [ F1724BA27E97D627F808FB0BA77A28A6 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
15:16:38.0134 6124 CompositeBus - ok
15:16:38.0153 6124 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
15:16:38.0154 6124 crcdisk - ok
15:16:38.0202 6124 [ 520A108A2657F4BCA7FCED9CA7D885DE ] CryptSvc C:\Windows\system32\cryptsvc.dll
15:16:38.0205 6124 CryptSvc - ok
15:16:38.0229 6124 [ 27C9490BDD0AE48911AB8CF1932591ED ] CSC C:\Windows\system32\drivers\csc.sys
15:16:38.0234 6124 CSC - ok
15:16:38.0269 6124 [ 56FB5F222EA30D3D3FC459879772CB73 ] CscService C:\Windows\System32\cscsvc.dll
15:16:38.0276 6124 CscService - ok
15:16:38.0324 6124 [ B82CD39E336973359D7C9BF911E8E84F ] DcomLaunch C:\Windows\system32\rpcss.dll
15:16:38.0333 6124 DcomLaunch - ok
15:16:38.0355 6124 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
15:16:38.0360 6124 defragsvc - ok
15:16:38.0400 6124 [ 83D1ECEA8FAAE75604C0FA49AC7AD996 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
15:16:38.0403 6124 DfsC - ok
15:16:38.0432 6124 [ C56495FBD770712367CAD35E5DE72DA6 ] Dhcp C:\Windows\system32\dhcpcore.dll
15:16:38.0437 6124 Dhcp - ok
15:16:38.0464 6124 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
15:16:38.0465 6124 discache - ok
15:16:38.0506 6124 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
15:16:38.0507 6124 Disk - ok
15:16:38.0535 6124 [ B15BE77A2BACF9C3177D27518AFE26A9 ] Dnscache C:\Windows\System32\dnsrslvr.dll
15:16:38.0538 6124 Dnscache - ok
15:16:38.0561 6124 [ 4408C85C21EEA48EB0CE486BAEEF0502 ] dot3svc C:\Windows\System32\dot3svc.dll
15:16:38.0566 6124 dot3svc - ok
15:16:38.0590 6124 [ 7FA81C6E11CAA594ADB52084DA73A1E5 ] DPS C:\Windows\system32\dps.dll
15:16:38.0593 6124 DPS - ok
15:16:38.0627 6124 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
15:16:38.0628 6124 drmkaud - ok
15:16:38.0673 6124 [ 687AF6BB383885FF6A64071B189A7F3E ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
15:16:38.0676 6124 dtsoftbus01 - ok
15:16:38.0732 6124 [ 1679A4669326CB1A67CC95658D273234 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
15:16:38.0740 6124 DXGKrnl - ok
15:16:38.0767 6124 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
15:16:38.0770 6124 EapHost - ok
15:16:38.0870 6124 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
15:16:38.0948 6124 ebdrv - ok
15:16:38.0990 6124 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] EFS C:\Windows\System32\lsass.exe
15:16:38.0993 6124 EFS - ok
15:16:39.0041 6124 [ 1697C39978CD69F6FBC15302EDCECE1F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
15:16:39.0049 6124 ehRecvr - ok
15:16:39.0070 6124 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
15:16:39.0072 6124 ehSched - ok
15:16:39.0112 6124 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
15:16:39.0117 6124 elxstor - ok
15:16:39.0154 6124 [ 539CA34FBC74EC366A0D751028C32A08 ] epmntdrv C:\Windows\system32\epmntdrv.sys
15:16:39.0158 6124 epmntdrv - ok
15:16:39.0175 6124 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
15:16:39.0176 6124 ErrDev - ok
15:16:39.0202 6124 [ 1F2F4AB15CE03ECC257FEB2F6DC5A013 ] EuGdiDrv C:\Windows\system32\EuGdiDrv.sys
15:16:39.0205 6124 EuGdiDrv - ok
15:16:39.0234 6124 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
15:16:39.0239 6124 EventSystem - ok
15:16:39.0261 6124 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
15:16:39.0264 6124 exfat - ok
15:16:39.0279 6124 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
15:16:39.0281 6124 fastfat - ok
15:16:39.0308 6124 [ F7EA23CC5E6BF2181F3F399D54F6EFC1 ] Fax C:\Windows\system32\fxssvc.exe
15:16:39.0315 6124 Fax - ok
15:16:39.0342 6124 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
15:16:39.0343 6124 fdc - ok
15:16:39.0363 6124 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
15:16:39.0365 6124 fdPHost - ok
15:16:39.0376 6124 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
15:16:39.0379 6124 FDResPub - ok
15:16:39.0394 6124 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
15:16:39.0395 6124 FileInfo - ok
15:16:39.0500 6124 [ 142A7AE58BD1ED496DC063196DB1527E ] FileMonitor C:\Program Files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys
15:16:39.0503 6124 FileMonitor - ok
15:16:39.0528 6124 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
15:16:39.0529 6124 Filetrace - ok
15:16:39.0593 6124 [ 227846995AFEEFA70D328BF5334A86A5 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
15:16:39.0604 6124 FLEXnet Licensing Service - ok
15:16:39.0620 6124 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
15:16:39.0621 6124 flpydisk - ok
15:16:39.0650 6124 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
15:16:39.0652 6124 FltMgr - ok
15:16:39.0703 6124 [ 7FE4995528A7529A761875151EE3D512 ] FontCache C:\Windows\system32\FntCache.dll
15:16:39.0718 6124 FontCache - ok
15:16:39.0766 6124 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
15:16:39.0769 6124 FontCache3.0.0.0 - ok
15:16:39.0800 6124 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
15:16:39.0802 6124 FsDepends - ok
15:16:39.0841 6124 [ 790A4CA68F44BE35967B3DF61F3E4675 ] FsUsbExDisk C:\Windows\system32\FsUsbExDisk.SYS
15:16:39.0846 6124 FsUsbExDisk - ok
15:16:39.0886 6124 [ D3F9205CC4CB07553F2F9472C767EA87 ] FsUsbExService C:\Windows\system32\FsUsbExService.Exe
15:16:39.0893 6124 FsUsbExService - ok
15:16:39.0921 6124 [ 500A9814FD9446A8126858A5A7F7D273 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
15:16:39.0923 6124 Fs_Rec - ok
15:16:39.0948 6124 [ DAFBD9FE39197495AED6D51F3B85B5D2 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
15:16:39.0952 6124 fvevol - ok
15:16:39.0987 6124 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
15:16:39.0989 6124 gagp30kx - ok
15:16:40.0041 6124 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
15:16:40.0043 6124 GEARAspiWDM - ok
15:16:40.0084 6124 [ 8BA3C04702BF8F927AB36AE8313CA4EE ] gpsvc C:\Windows\System32\gpsvc.dll
15:16:40.0096 6124 gpsvc - ok
15:16:40.0178 6124 [ E859CA020ED61899F3C74A8D0032D05C ] Guard.Mail.ru C:\Program Files\Guard-ICQ\GuardICQ.exe
15:16:40.0202 6124 Guard.Mail.ru - ok
15:16:40.0240 6124 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
15:16:40.0243 6124 gupdate - ok
15:16:40.0255 6124 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
15:16:40.0258 6124 gupdatem - ok
15:16:40.0288 6124 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
15:16:40.0289 6124 hcw85cir - ok
15:16:40.0340 6124 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
15:16:40.0343 6124 HdAudAddService - ok
15:16:40.0364 6124 [ 717A2207FD6F13AD3E664C7D5A43C7BF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
15:16:40.0365 6124 HDAudBus - ok
15:16:40.0377 6124 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
15:16:40.0378 6124 HidBatt - ok
15:16:40.0386 6124 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
15:16:40.0387 6124 HidBth - ok
15:16:40.0416 6124 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
15:16:40.0418 6124 HidIr - ok
15:16:40.0454 6124 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll
15:16:40.0535 6124 hidserv - ok
15:16:40.0589 6124 [ 25072FB35AC90B25F9E4E3BACF774102 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
15:16:40.0591 6124 HidUsb - ok
15:16:40.0633 6124 [ 741C2A45CA8407E374AABA3E330B7872 ] hkmsvc C:\Windows\system32\kmsvc.dll
15:16:40.0649 6124 hkmsvc - ok
15:16:40.0726 6124 [ A768CA158BB06782A2835B907F4873C3 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
15:16:40.0757 6124 HomeGroupListener - ok
15:16:40.0889 6124 [ FB08DEC5EF43D0C66D83B8E9694E7549 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
15:16:40.0946 6124 HomeGroupProvider - ok
15:16:40.0990 6124 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
15:16:41.0009 6124 HpSAMD - ok
15:16:41.0155 6124 [ C531C7FD9E8B62021112787C4E2C5A5A ] HTTP C:\Windows\system32\drivers\HTTP.sys
15:16:41.0189 6124 HTTP - ok
15:16:41.0236 6124 [ 8305F33CDE89AD6C7A0763ED0B5A8D42 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
15:16:41.0237 6124 hwpolicy - ok
15:16:41.0298 6124 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
15:16:41.0314 6124 i8042prt - ok
15:16:41.0405 6124 [ 71F1A494FEDF4B33C02C4A6A28D6D9E9 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
15:16:41.0409 6124 iaStorV - ok
15:16:41.0535 6124 [ 9AC1E19D77BA038F24E2FAB5D95F70D3 ] ICQ Service C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
15:16:41.0555 6124 ICQ Service - ok
15:16:41.0647 6124 [ 5AF815EB5BC9802E5A064E2BA62BFC0C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:16:41.0674 6124 idsvc - ok
15:16:41.0742 6124 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
15:16:41.0744 6124 iirsp - ok
15:16:41.0850 6124 [ FAC0EE6562B121B1399D6E855583F7A5 ] IKEEXT C:\Windows\System32\ikeext.dll
15:16:41.0873 6124 IKEEXT - ok
15:16:41.0972 6124 [ 8AE99EBE30E8338907361018D9030835 ] IMFservice C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
15:16:42.0006 6124 IMFservice - ok
15:16:42.0038 6124 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
15:16:42.0055 6124 intelide - ok
15:16:42.0107 6124 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
15:16:42.0109 6124 intelppm - ok
15:16:42.0152 6124 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
15:16:42.0173 6124 IPBusEnum - ok
15:16:42.0255 6124 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:16:42.0271 6124 IpFilterDriver - ok
15:16:42.0340 6124 [ 477397B432A256A50EE7E4339EB9EA14 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
15:16:42.0359 6124 iphlpsvc - ok
15:16:42.0384 6124 [ E4454B6C37D7FFD5649611F6496308A7 ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
15:16:42.0394 6124 IPMIDRV - ok
15:16:42.0410 6124 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
15:16:42.0421 6124 IPNAT - ok
15:16:42.0528 6124 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
15:16:42.0545 6124 IRENUM - ok
15:16:42.0597 6124 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
15:16:42.0614 6124 isapnp - ok
15:16:42.0660 6124 [ ED46C223AE46C6866AB77CDC41C404B7 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
15:16:42.0662 6124 iScsiPrt - ok
15:16:42.0781 6124 [ 09BC1A8800F7A6E66926B8C9E02A396B ] k57nd60x C:\Windows\system32\DRIVERS\k57nd60x.sys
15:16:42.0797 6124 k57nd60x - ok
15:16:42.0890 6124 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
15:16:42.0906 6124 kbdclass - ok
15:16:42.0953 6124 [ 3D9F0EBF350EDCFD6498057301455964 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
15:16:42.0953 6124 kbdhid - ok
15:16:43.0000 6124 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] KeyIso C:\Windows\system32\lsass.exe
15:16:43.0000 6124 KeyIso - ok
15:16:43.0093 6124 [ 52FC17C8589F11747D01D3CF592673D0 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
15:16:43.0109 6124 KSecDD - ok
15:16:43.0187 6124 [ 3E5474B03568CFAB834DA3C38E8C9EFA ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
15:16:43.0234 6124 KSecPkg - ok
15:16:43.0280 6124 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
15:16:43.0327 6124 KtmRm - ok
15:16:43.0421 6124 [ 8F6BF790D3168224C16F2AF68A84438C ] LanmanServer C:\Windows\System32\srvsvc.dll
15:16:43.0436 6124 LanmanServer - ok
15:16:43.0483 6124 [ B9891F885DCF1F0513A51CB58493CB1F ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:16:43.0483 6124 LanmanWorkstation - ok
15:16:43.0592 6124 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
15:16:43.0608 6124 lltdio - ok
15:16:43.0655 6124 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
15:16:43.0670 6124 lltdsvc - ok
15:16:43.0686 6124 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
15:16:43.0702 6124 lmhosts - ok
15:16:43.0780 6124 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
15:16:43.0795 6124 LSI_FC - ok
15:16:43.0826 6124 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
15:16:43.0842 6124 LSI_SAS - ok
15:16:43.0920 6124 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
15:16:43.0936 6124 LSI_SAS2 - ok
15:16:43.0967 6124 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
15:16:43.0982 6124 LSI_SCSI - ok
15:16:44.0045 6124 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
15:16:44.0045 6124 luafv - ok
15:16:44.0107 6124 [ E2B0887816ED336685954E3D8FDAA51D ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
15:16:44.0107 6124 Mcx2Svc - ok
15:16:44.0138 6124 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
15:16:44.0138 6124 megasas - ok
15:16:44.0170 6124 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
15:16:44.0170 6124 MegaSR - ok
15:16:44.0232 6124 [ 123271BD5237AB991DC5C21FDF8835EB ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
15:16:44.0248 6124 Microsoft Office Groove Audit Service - ok
15:16:44.0294 6124 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
15:16:44.0294 6124 MMCSS - ok
15:16:44.0326 6124 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
15:16:44.0341 6124 Modem - ok
15:16:44.0404 6124 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
15:16:44.0404 6124 monitor - ok
15:16:44.0435 6124 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
15:16:44.0435 6124 mouclass - ok
15:16:44.0450 6124 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
15:16:44.0466 6124 mouhid - ok
15:16:44.0482 6124 [ 921C18727C5920D6C0300736646931C2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
15:16:44.0482 6124 mountmgr - ok
15:16:44.0575 6124 [ 2AF5997438C55FB79D33D015C30E1974 ] mpio C:\Windows\system32\DRIVERS\mpio.sys
15:16:44.0575 6124 mpio - ok
15:16:44.0591 6124 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
15:16:44.0591 6124 mpsdrv - ok
15:16:44.0622 6124 [ 5CD996CECF45CBC3E8D109C86B82D69E ] MpsSvc C:\Windows\system32\mpssvc.dll
15:16:44.0638 6124 MpsSvc - ok
15:16:44.0669 6124 [ B1BE47008D20E43DA3ADC37C24CDB89D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
15:16:44.0669 6124 MRxDAV - ok
15:16:44.0716 6124 [ CA7570E42522E24324A12161DB14EC02 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
15:16:44.0716 6124 mrxsmb - ok
15:16:44.0747 6124 [ F965C3AB2B2AE5C378F4562486E35051 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:16:44.0747 6124 mrxsmb10 - ok
15:16:44.0762 6124 [ 25C38264A3C72594DD21D355D70D7A5D ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:16:44.0762 6124 mrxsmb20 - ok
15:16:44.0794 6124 [ 4326D168944123F38DD3B2D9C37A0B12 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
15:16:44.0794 6124 msahci - ok
15:16:44.0809 6124 [ 455029C7174A2DBB03DBA8A0D8BDDD9A ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
15:16:44.0809 6124 msdsm - ok
15:16:44.0825 6124 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
15:16:44.0840 6124 MSDTC - ok
15:16:44.0856 6124 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
15:16:44.0856 6124 Msfs - ok
15:16:44.0872 6124 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
15:16:44.0872 6124 mshidkmdf - ok
15:16:44.0887 6124 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
15:16:44.0887 6124 msisadrv - ok
15:16:44.0934 6124 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
15:16:44.0934 6124 MSiSCSI - ok
15:16:44.0934 6124 msiserver - ok
15:16:44.0965 6124 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
15:16:44.0965 6124 MSKSSRV - ok
15:16:44.0996 6124 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
15:16:44.0996 6124 MSPCLOCK - ok
15:16:45.0012 6124 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
15:16:45.0012 6124 MSPQM - ok
15:16:45.0028 6124 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
15:16:45.0028 6124 MsRPC - ok
15:16:45.0043 6124 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
15:16:45.0043 6124 mssmbios - ok
15:16:45.0074 6124 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
15:16:45.0074 6124 MSTEE - ok
15:16:45.0090 6124 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
15:16:45.0090 6124 MTConfig - ok
15:16:45.0106 6124 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
15:16:45.0106 6124 Mup - ok
15:16:45.0137 6124 [ 80284F1985C70C86F0B5F86DA2DFE1DF ] napagent C:\Windows\system32\qagentRT.dll
15:16:45.0137 6124 napagent - ok
15:16:45.0184 6124 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
15:16:45.0184 6124 NativeWifiP - ok
15:16:45.0230 6124 [ 23759D175A0A9BAAF04D05047BC135A8 ] NDIS C:\Windows\system32\drivers\ndis.sys
15:16:45.0230 6124 NDIS - ok
15:16:45.0262 6124 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
15:16:45.0262 6124 NdisCap - ok
15:16:45.0293 6124 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
15:16:45.0293 6124 NdisTapi - ok
15:16:45.0308 6124 [ B30AE7F2B6D7E343B0DF32E6C08FCE75 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
15:16:45.0324 6124 Ndisuio - ok
15:16:45.0355 6124 [ 267C415EADCBE53C9CA873DEE39CF3A4 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
15:16:45.0355 6124 NdisWan - ok
15:16:45.0386 6124 [ AF7E7C63DCEF3F8772726F86039D6EB4 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
15:16:45.0386 6124 NDProxy - ok
15:16:45.0418 6124 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
15:16:45.0418 6124 NetBIOS - ok
15:16:45.0433 6124 [ DD52A733BF4CA5AF84562A5E2F963B91 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
15:16:45.0433 6124 NetBT - ok
15:16:45.0449 6124 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] Netlogon C:\Windows\system32\lsass.exe
15:16:45.0449 6124 Netlogon - ok
15:16:45.0496 6124 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
15:16:45.0496 6124 Netman - ok
15:16:45.0511 6124 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
15:16:45.0527 6124 netprofm - ok
15:16:45.0558 6124 [ FE2AA5A684B0DD9B1FAE57B7817C198B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:16:45.0558 6124 NetTcpPortSharing - ok
15:16:45.0589 6124 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
15:16:45.0605 6124 nfrd960 - ok
15:16:45.0620 6124 [ 2226496E34BD40734946A054B1CD657F ] NlaSvc C:\Windows\System32\nlasvc.dll
15:16:45.0620 6124 NlaSvc - ok
15:16:45.0652 6124 [ B0A67DE1A128389AEA4D42C5A56215FD ] nmwcd C:\Windows\system32\drivers\ccdcmb.sys
15:16:45.0652 6124 nmwcd - ok
15:16:45.0683 6124 [ 025C54F9F8C8BC1894EA38529C742C54 ] nmwcdc C:\Windows\system32\drivers\ccdcmbo.sys
15:16:45.0683 6124 nmwcdc - ok
15:16:45.0698 6124 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
15:16:45.0698 6124 Npfs - ok
15:16:45.0714 6124 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
15:16:45.0714 6124 nsi - ok
15:16:45.0745 6124 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
15:16:45.0745 6124 nsiproxy - ok
15:16:45.0792 6124 [ 187002CE05693C306F43C873F821381F ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
15:16:45.0808 6124 Ntfs - ok
15:16:45.0839 6124 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
15:16:45.0839 6124 Null - ok
15:16:45.0854 6124 [ F1B0BED906F97E16F6D0C3629D2F21C6 ] nvraid C:\Windows\system32\drivers\nvraid.sys
15:16:45.0854 6124 nvraid - ok
15:16:45.0886 6124 [ 4520B63899E867F354EE012D34E11536 ] nvstor C:\Windows\system32\drivers\nvstor.sys
15:16:45.0886 6124 nvstor - ok
15:16:45.0901 6124 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
15:16:45.0901 6124 nv_agp - ok
15:16:45.0995 6124 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:16:46.0057 6124 odserv - ok
15:16:46.0104 6124 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
15:16:46.0104 6124 ohci1394 - ok
15:16:46.0244 6124 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:16:46.0244 6124 ose - ok
15:16:46.0276 6124 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
15:16:46.0291 6124 p2pimsvc - ok
15:16:46.0307 6124 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
15:16:46.0322 6124 p2psvc - ok
15:16:46.0354 6124 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
15:16:46.0354 6124 Parport - ok
15:16:46.0400 6124 [ 66D3415C159741ADE7038A277EFFF99F ] partmgr C:\Windows\system32\drivers\partmgr.sys
15:16:46.0400 6124 partmgr - ok
15:16:46.0416 6124 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
15:16:46.0416 6124 Parvdm - ok
15:16:46.0447 6124 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
15:16:46.0447 6124 PcaSvc - ok
15:16:46.0510 6124 [ 175CC28DCF819F78CAA3FBD44AD9E52A ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfd.sys
15:16:46.0510 6124 pccsmcfd - ok
15:16:46.0541 6124 [ C858CB77C577780ECC456A892E7E7D0F ] pci C:\Windows\system32\DRIVERS\pci.sys
15:16:46.0541 6124 pci - ok
15:16:46.0572 6124 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\DRIVERS\pciide.sys
15:16:46.0572 6124 pciide - ok
15:16:46.0588 6124 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
15:16:46.0588 6124 pcmcia - ok
15:16:46.0603 6124 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
15:16:46.0603 6124 pcw - ok
15:16:46.0650 6124 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
15:16:46.0666 6124 PEAUTH - ok
15:16:46.0712 6124 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
15:16:46.0728 6124 PeerDistSvc - ok
15:16:46.0790 6124 [ 9C1BFF7910C89A1D12E57343475840CB ] pla C:\Windows\system32\pla.dll
15:16:46.0806 6124 pla - ok
15:16:46.0837 6124 [ 71DEF5EC79774C798342D0EA16E41780 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
15:16:46.0853 6124 PlugPlay - ok
15:16:46.0868 6124 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
15:16:46.0868 6124 PNRPAutoReg - ok
15:16:46.0900 6124 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
15:16:46.0900 6124 PNRPsvc - ok
15:16:46.0946 6124 [ 48E1B75C6DC0232FD92BAAE4BD344721 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
15:16:46.0946 6124 PolicyAgent - ok
15:16:46.0978 6124 [ DBFF83F709A91049621C1D35DD45C92C ] Power C:\Windows\system32\umpo.dll
15:16:46.0993 6124 Power - ok
15:16:47.0024 6124 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
15:16:47.0024 6124 PptpMiniport - ok
15:16:47.0056 6124 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
15:16:47.0056 6124 Processor - ok
15:16:47.0102 6124 [ AEA3BDBDBA667AA6F678CB38907E4F5E ] ProfSvc C:\Windows\system32\profsvc.dll
15:16:47.0118 6124 ProfSvc - ok
15:16:47.0134 6124 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] ProtectedStorage C:\Windows\system32\lsass.exe
15:16:47.0134 6124 ProtectedStorage - ok
15:16:47.0165 6124 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
15:16:47.0165 6124 Psched - ok
15:16:47.0212 6124 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
15:16:47.0227 6124 ql2300 - ok
15:16:47.0258 6124 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
15:16:47.0258 6124 ql40xx - ok
15:16:47.0290 6124 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
15:16:47.0305 6124 QWAVE - ok
15:16:47.0321 6124 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
15:16:47.0321 6124 QWAVEdrv - ok
15:16:47.0321 6124 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
15:16:47.0336 6124 RasAcd - ok
15:16:47.0368 6124 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
15:16:47.0368 6124 RasAgileVpn - ok
15:16:47.0383 6124 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
15:16:47.0399 6124 RasAuto - ok
15:16:47.0414 6124 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
15:16:47.0414 6124 Rasl2tp - ok
15:16:47.0430 6124 [ 0CE66EC736B7FC526D78F7624C7D2A94 ] RasMan C:\Windows\System32\rasmans.dll
15:16:47.0446 6124 RasMan - ok
15:16:47.0461 6124 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
15:16:47.0461 6124 RasPppoe - ok
15:16:47.0492 6124 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
15:16:47.0492 6124 RasSstp - ok
15:16:47.0508 6124 [ 835D7E81BF517A3B72384BDCC85E1CE6 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
15:16:47.0508 6124 rdbss - ok
15:16:47.0524 6124 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
15:16:47.0524 6124 rdpbus - ok
15:16:47.0539 6124 [ 1E016846895B15A99F9A176A05029075 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
15:16:47.0539 6124 RDPCDD - ok
15:16:47.0555 6124 [ C5FF95883FFEF704D50C40D21CFB3AB5 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
15:16:47.0570 6124 RDPDR - ok
15:16:47.0586 6124 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
15:16:47.0586 6124 RDPENCDD - ok
15:16:47.0586 6124 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
15:16:47.0586 6124 RDPREFMP - ok
15:16:47.0617 6124 [ C5B8D47A4688DE9D335204EA757C2240 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
15:16:47.0617 6124 RDPWD - ok
15:16:47.0664 6124 [ 4EA225BF1CF05E158853F30A99CA29A7 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
15:16:47.0664 6124 rdyboost - ok
15:16:47.0695 6124 [ 169C4D45DFCFC2E1027CFBFC2015F142 ] RegFilter C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys
15:16:47.0695 6124 RegFilter - ok
15:16:47.0726 6124 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
15:16:47.0726 6124 RemoteAccess - ok
15:16:47.0773 6124 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
15:16:47.0773 6124 RemoteRegistry - ok
15:16:47.0820 6124 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
15:16:47.0820 6124 RFCOMM - ok
15:16:47.0851 6124 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
15:16:47.0867 6124 RpcEptMapper - ok
15:16:47.0882 6124 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
15:16:47.0898 6124 RpcLocator - ok
15:16:47.0914 6124 [ B82CD39E336973359D7C9BF911E8E84F ] RpcSs C:\Windows\system32\rpcss.dll
15:16:47.0929 6124 RpcSs - ok
15:16:47.0960 6124 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
15:16:47.0960 6124 rspndr - ok
15:16:47.0976 6124 [ 5423D8437051E89DD34749F242C98648 ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
15:16:47.0992 6124 s3cap - ok
15:16:48.0007 6124 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] SamSs C:\Windows\system32\lsass.exe
15:16:48.0007 6124 SamSs - ok
15:16:48.0038 6124 [ 34EE0C44B724E3E4CE2EFF29126DE5B5 ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
15:16:48.0038 6124 sbp2port - ok
15:16:48.0054 6124 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
15:16:48.0070 6124 SCardSvr - ok
15:16:48.0085 6124 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
15:16:48.0085 6124 scfilter - ok
15:16:48.0116 6124 [ DF1E5C82E4D09CF8105CC644980C4803 ] Schedule C:\Windows\system32\schedsvc.dll
15:16:48.0132 6124 Schedule - ok
15:16:48.0148 6124 [ 628A9E30EC5E18DD5DE6BE4DBDC12198 ] SCPolicySvc C:\Windows\System32\certprop.dll
15:16:48.0148 6124 SCPolicySvc - ok
15:16:48.0163 6124 [ 5FD90ABDBFAEE85986802622CBB03446 ] SDRSVC C:\Windows\System32\SDRSVC.dll
15:16:48.0163 6124 SDRSVC - ok
15:16:48.0194 6124 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
15:16:48.0194 6124 secdrv - ok
15:16:48.0226 6124 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
15:16:48.0226 6124 seclogon - ok
15:16:48.0226 6124 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
15:16:48.0241 6124 SENS - ok
15:16:48.0241 6124 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
15:16:48.0257 6124 SensrSvc - ok
15:16:48.0272 6124 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
15:16:48.0272 6124 Serenum - ok
15:16:48.0288 6124 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
15:16:48.0288 6124 Serial - ok
15:16:48.0304 6124 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
15:16:48.0304 6124 sermouse - ok
15:16:48.0366 6124 [ 9D38320BB32230349379DF5DDBBF7FCE ] ServiceLayer C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
15:16:48.0382 6124 ServiceLayer - ok
15:16:48.0413 6124 [ 8F55CE568C543D5ADF45C409D16718FC ] SessionEnv C:\Windows\system32\sessenv.dll
15:16:48.0428 6124 SessionEnv - ok
15:16:48.0460 6124 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
15:16:48.0460 6124 sffdisk - ok
15:16:48.0475 6124 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
15:16:48.0475 6124 sffp_mmc - ok
15:16:48.0491 6124 [ A0708BBD07D245C06FF9DE549CA47185 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
15:16:48.0491 6124 sffp_sd - ok
15:16:48.0522 6124 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
15:16:48.0538 6124 sfloppy - ok
15:16:48.0553 6124 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
15:16:48.0553 6124 SharedAccess - ok
15:16:48.0584 6124 [ CD2E48FA5B29EE2B3B5858056D246EF2 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:16:48.0584 6124 ShellHWDetection - ok
15:16:48.0600 6124 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
15:16:48.0600 6124 sisagp - ok
15:16:48.0616 6124 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
15:16:48.0631 6124 SiSRaid2 - ok
15:16:48.0631 6124 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
15:16:48.0647 6124 SiSRaid4 - ok
15:16:48.0709 6124 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
15:16:48.0709 6124 Smb - ok
15:16:48.0756 6124 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
15:16:48.0772 6124 SNMPTRAP - ok
15:16:48.0787 6124 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
15:16:48.0787 6124 spldr - ok
15:16:48.0818 6124 [ E17323B0AA9FB3FF9945731D736EDA2F ] Spooler C:\Windows\System32\spoolsv.exe
15:16:48.0834 6124 Spooler - ok
15:16:48.0928 6124 [ 4C287F9069FEDBD791178876EE9DE536 ] sppsvc C:\Windows\system32\sppsvc.exe
15:16:49.0006 6124 sppsvc - ok
15:16:49.0021 6124 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7 ] sppuinotify C:\Windows\system32\sppuinotify.dll
15:16:49.0021 6124 sppuinotify - ok
15:16:49.0084 6124 [ AB5C8F6E63674DBAD9C1E449E8FD77CE ] sptd C:\Windows\System32\Drivers\sptd.sys
15:16:49.0099 6124 sptd - ok
15:16:49.0115 6124 [ C4A027B8C0BD3FC0699F41FA5E9E0C87 ] srv C:\Windows\system32\DRIVERS\srv.sys
15:16:49.0130 6124 srv - ok
15:16:49.0146 6124 [ 414BB592CAD8A79649D01F9D94318FB3 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
15:16:49.0146 6124 srv2 - ok
15:16:49.0162 6124 [ FF207D67700AA18242AAF985D3E7D8F4 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
15:16:49.0162 6124 srvnet - ok
15:16:49.0193 6124 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
15:16:49.0208 6124 SSDPSRV - ok
15:16:49.0224 6124 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
15:16:49.0224 6124 SstpSvc - ok
15:16:49.0271 6124 [ EAA66218CD39F5BB1B4853A78C67C787 ] ss_bbus C:\Windows\system32\DRIVERS\ss_bbus.sys
15:16:49.0271 6124 ss_bbus - ok
15:16:49.0286 6124 [ 91765F99914ED8693D8BC76524F21581 ] ss_bmdfl C:\Windows\system32\DRIVERS\ss_bmdfl.sys
15:16:49.0286 6124 ss_bmdfl - ok
15:16:49.0302 6124 [ 840E7B738B03C10EE91D9B7D3D6EFF15 ] ss_bmdm C:\Windows\system32\DRIVERS\ss_bmdm.sys
15:16:49.0302 6124 ss_bmdm - ok
15:16:49.0333 6124 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
15:16:49.0333 6124 stexstor - ok
15:16:49.0364 6124 [ A22825E7BB7018E8AF3E229A5AF17221 ] StiSvc C:\Windows\System32\wiaservc.dll
15:16:49.0380 6124 StiSvc - ok
15:16:49.0396 6124 [ 957E346CA948668F2496A6CCF6FF82CC ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
15:16:49.0396 6124 storflt - ok
15:16:49.0411 6124 [ D5751969DC3E4B88BF482AC8EC9FE019 ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
15:16:49.0411 6124 storvsc - ok
15:16:49.0442 6124 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
15:16:49.0442 6124 swenum - ok
15:16:49.0458 6124 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
15:16:49.0458 6124 swprv - ok
15:16:49.0505 6124 [ 47183E3520C88FADD5B0C87D57040DA5 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
15:16:49.0505 6124 SynTP - ok
15:16:49.0536 6124 [ 04105C8DA62353589C29BDAEB8D88BD8 ] SysMain C:\Windows\system32\sysmain.dll
15:16:49.0552 6124 SysMain - ok
15:16:49.0583 6124 [ FCFB6C552FBC0DA299799CBD50AD9FD4 ] TabletInputService C:\Windows\System32\TabSvc.dll
15:16:49.0583 6124 TabletInputService - ok
15:16:49.0614 6124 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF ] TapiSrv C:\Windows\System32\tapisrv.dll
15:16:49.0614 6124 TapiSrv - ok
15:16:49.0630 6124 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
15:16:49.0645 6124 TBS - ok
15:16:49.0692 6124 [ 55E9965552741F3850CB22CBBA9671ED ] Tcpip C:\Windows\system32\drivers\tcpip.sys
15:16:49.0708 6124 Tcpip - ok
15:16:49.0739 6124 [ 55E9965552741F3850CB22CBBA9671ED ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
15:16:49.0754 6124 TCPIP6 - ok
15:16:49.0786 6124 [ E64444523ADD154F86567C469BC0B17F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
15:16:49.0786 6124 tcpipreg - ok
15:16:49.0801 6124 [ 1875C1490D99E70E449E3AFAE9FCBADF ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
15:16:49.0801 6124 TDPIPE - ok
15:16:49.0817 6124 [ 7156308896D34EA75A582F9A09E50C17 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
15:16:49.0817 6124 TDTCP - ok
15:16:49.0848 6124 [ CB39E896A2A83702D1737BFD402B3542 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
15:16:49.0848 6124 tdx - ok
15:16:49.0864 6124 [ C36F41EE20E6999DBF4B0425963268A5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
15:16:49.0864 6124 TermDD - ok
15:16:49.0895 6124 [ A01E50A04D7B1960B33E92B9080E6A94 ] TermService C:\Windows\System32\termsrv.dll

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 14 zář 2012 15:18

15:16:49.0910 6124 TermService - ok
15:16:49.0926 6124 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
15:16:49.0926 6124 Themes - ok
15:16:49.0942 6124 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
15:16:49.0942 6124 THREADORDER - ok
15:16:49.0973 6124 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
15:16:49.0973 6124 TrkWks - ok
15:16:50.0020 6124 [ 41A4C781D2286208D397D72099304133 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:16:50.0020 6124 TrustedInstaller - ok
15:16:50.0051 6124 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
15:16:50.0051 6124 tssecsrv - ok
15:16:50.0098 6124 [ 3E461D890A97F9D4C168F5FDA36E1D00 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
15:16:50.0098 6124 tunnel - ok
15:16:50.0113 6124 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
15:16:50.0113 6124 uagp35 - ok
15:16:50.0144 6124 [ 09CC3E16F8E5EE7168E01CF8FCBE061A ] udfs C:\Windows\system32\DRIVERS\udfs.sys
15:16:50.0144 6124 udfs - ok
15:16:50.0191 6124 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
15:16:50.0191 6124 UI0Detect - ok
15:16:50.0254 6124 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
15:16:50.0254 6124 uliagpkx - ok
15:16:50.0285 6124 [ 049B3A50B3D646BAEEEE9EEC9B0668DC ] umbus C:\Windows\system32\DRIVERS\umbus.sys
15:16:50.0285 6124 umbus - ok
15:16:50.0300 6124 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
15:16:50.0300 6124 UmPass - ok
15:16:50.0316 6124 [ 8ECACA5454844F66386F7BE4AE0D7CD1 ] UmRdpService C:\Windows\System32\umrdp.dll
15:16:50.0332 6124 UmRdpService - ok
15:16:50.0363 6124 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
15:16:50.0363 6124 upnphost - ok
15:16:50.0394 6124 [ 78B74AF8727A28C128E164E9B53A5413 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
15:16:50.0394 6124 upperdev - ok
15:16:50.0441 6124 [ BAD56000F6F64C8E98F67DAFE6EB7444 ] UrlFilter C:\Program Files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys
15:16:50.0441 6124 UrlFilter - ok
15:16:50.0488 6124 [ C31AE588E403042632DC796CF09E30B0 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
15:16:50.0488 6124 usbccgp - ok
15:16:50.0534 6124 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
15:16:50.0534 6124 usbcir - ok
15:16:50.0550 6124 [ E4C436D914768CE965D5E659BA7EEBD8 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
15:16:50.0550 6124 usbehci - ok
15:16:50.0581 6124 [ BDCD7156EC37448F08633FD899823620 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
15:16:50.0581 6124 usbhub - ok
15:16:50.0612 6124 [ EB2D819A639015253C871CDA09D91D58 ] usbohci C:\Windows\system32\drivers\usbohci.sys
15:16:50.0612 6124 usbohci - ok
15:16:50.0644 6124 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
15:16:50.0644 6124 usbprint - ok
15:16:50.0675 6124 [ 88701ECA76145E2C011C0EEFF0F7B70E ] usbser C:\Windows\system32\drivers\usbser.sys
15:16:50.0690 6124 usbser - ok
15:16:50.0706 6124 [ 4F8FBC51A1C0A17310846B417A447F91 ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
15:16:50.0706 6124 UsbserFilt - ok
15:16:50.0722 6124 [ 1C4287739A93594E57E2A9E6A3ED7353 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
15:16:50.0722 6124 USBSTOR - ok
15:16:50.0753 6124 [ 22480BF4E5A09192E5E30BA4DDE79FA4 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
15:16:50.0753 6124 usbuhci - ok
15:16:50.0784 6124 [ B5F6A992D996282B7FAE7048E50AF83A ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
15:16:50.0800 6124 usbvideo - ok
15:16:50.0815 6124 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
15:16:50.0862 6124 UxSms - ok
15:16:50.0878 6124 [ C2243FF9E9AAD0C30E8B1A0914DA15B6 ] VaultSvc C:\Windows\system32\lsass.exe
15:16:50.0893 6124 VaultSvc - ok
15:16:51.0034 6124 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
15:16:51.0034 6124 vdrvroot - ok
15:16:51.0127 6124 [ 8C4E7C49D3641BC9E299E466A7F8867D ] vds C:\Windows\System32\vds.exe
15:16:51.0143 6124 vds - ok
15:16:51.0158 6124 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
15:16:51.0158 6124 vga - ok
15:16:51.0174 6124 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
15:16:51.0174 6124 VgaSave - ok
15:16:51.0205 6124 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583 ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
15:16:51.0221 6124 vhdmp - ok
15:16:51.0361 6124 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
15:16:51.0361 6124 viaagp - ok
15:16:51.0377 6124 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
15:16:51.0377 6124 ViaC7 - ok
15:16:51.0392 6124 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\DRIVERS\viaide.sys
15:16:51.0408 6124 viaide - ok
15:16:51.0424 6124 [ 379B349F65F453D2A6E75EA6B7448E49 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
15:16:51.0424 6124 vmbus - ok
15:16:51.0439 6124 [ EC2BBAB4B84D0738C6C83D2234DC36FE ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
15:16:51.0439 6124 VMBusHID - ok
15:16:51.0455 6124 [ 384E5A2AA49934295171E499F86BA6F3 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
15:16:51.0455 6124 volmgr - ok
15:16:51.0486 6124 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
15:16:51.0486 6124 volmgrx - ok
15:16:51.0502 6124 [ 58DF9D2481A56EDDE167E51B334D44FD ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
15:16:51.0502 6124 volsnap - ok
15:16:51.0564 6124 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
15:16:51.0564 6124 vsmraid - ok
15:16:51.0673 6124 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C ] VSS C:\Windows\system32\vssvc.exe
15:16:51.0720 6124 VSS - ok
15:16:51.0736 6124 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
15:16:51.0736 6124 vwifibus - ok
15:16:51.0782 6124 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
15:16:51.0782 6124 vwififlt - ok
15:16:51.0860 6124 [ A3F04CBEA6C2A10E6CB01F8B47611882 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
15:16:51.0860 6124 vwifimp - ok
15:16:51.0954 6124 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
15:16:52.0001 6124 W32Time - ok
15:16:52.0048 6124 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
15:16:52.0048 6124 WacomPen - ok
15:16:52.0126 6124 [ 692A712062146E96D28BA0B7D75DE31B ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
15:16:52.0126 6124 WANARP - ok
15:16:52.0188 6124 [ 692A712062146E96D28BA0B7D75DE31B ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
15:16:52.0188 6124 Wanarpv6 - ok
15:16:52.0469 6124 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
15:16:52.0516 6124 WatAdminSvc - ok
15:16:52.0640 6124 [ 7790B77FE1E5EE47DCC66247095BB4C9 ] wbengine C:\Windows\system32\wbengine.exe
15:16:52.0703 6124 wbengine - ok
15:16:52.0703 6124 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
15:16:52.0718 6124 WbioSrvc - ok
15:16:52.0750 6124 [ 6D9B75275C3E3A5F51AEF81AFFADB2B6 ] wcncsvc C:\Windows\System32\wcncsvc.dll
15:16:52.0765 6124 wcncsvc - ok
15:16:52.0796 6124 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
15:16:52.0796 6124 WcsPlugInService - ok
15:16:52.0828 6124 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\DRIVERS\wd.sys
15:16:52.0828 6124 Wd - ok
15:16:52.0859 6124 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
15:16:52.0874 6124 Wdf01000 - ok
15:16:52.0890 6124 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
15:16:52.0890 6124 WdiServiceHost - ok
15:16:52.0906 6124 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
15:16:52.0906 6124 WdiSystemHost - ok
15:16:52.0937 6124 [ BB5EC38F8D4600119B4720BC5D4211F1 ] WebClient C:\Windows\System32\webclnt.dll
15:16:52.0937 6124 WebClient - ok
15:16:52.0968 6124 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
15:16:52.0968 6124 Wecsvc - ok
15:16:52.0999 6124 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
15:16:52.0999 6124 wercplsupport - ok
15:16:53.0030 6124 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
15:16:53.0030 6124 WerSvc - ok
15:16:53.0062 6124 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
15:16:53.0062 6124 WfpLwf - ok
15:16:53.0077 6124 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
15:16:53.0077 6124 WIMMount - ok
15:16:53.0124 6124 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
15:16:53.0124 6124 WinDefend - ok
15:16:53.0140 6124 WinHttpAutoProxySvc - ok
15:16:53.0186 6124 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
15:16:53.0186 6124 Winmgmt - ok
15:16:53.0249 6124 [ C4F5D3901D1B41D602DDC196E0B95B51 ] WinRM C:\Windows\system32\WsmSvc.dll
15:16:53.0264 6124 WinRM - ok
15:16:53.0296 6124 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
15:16:53.0311 6124 Wlansvc - ok
15:16:53.0342 6124 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
15:16:53.0342 6124 WmiAcpi - ok
15:16:53.0374 6124 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
15:16:53.0374 6124 wmiApSrv - ok
15:16:53.0436 6124 [ 77FBD400984CF72BA0FC4B3489D65F74 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
15:16:53.0452 6124 WMPNetworkSvc - ok
15:16:53.0483 6124 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
15:16:53.0498 6124 WPCSvc - ok
15:16:53.0514 6124 [ B7F658A2EBC07129538AD9AB35212637 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
15:16:53.0530 6124 WPDBusEnum - ok
15:16:53.0545 6124 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
15:16:53.0545 6124 ws2ifsl - ok
15:16:53.0561 6124 [ A661A76333057B383A06E65F0073222F ] wscsvc C:\Windows\system32\wscsvc.dll
15:16:53.0576 6124 wscsvc - ok
15:16:53.0576 6124 WSearch - ok
15:16:53.0654 6124 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
15:16:53.0686 6124 wuauserv - ok
15:16:53.0717 6124 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
15:16:53.0717 6124 WudfPf - ok
15:16:53.0748 6124 [ F91FF1E51FCA30B3C3981DB7D5924252 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
15:16:53.0748 6124 WUDFRd - ok
15:16:53.0779 6124 [ DDEE3682FE97037C45F4D7AB467CB8B6 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
15:16:53.0779 6124 wudfsvc - ok
15:16:53.0810 6124 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
15:16:53.0810 6124 WwanSvc - ok
15:16:53.0826 6124 ================ Scan global ===============================
15:16:53.0842 6124 [ 9A595DF601070DA78C40481120DD2C06 ] C:\Windows\system32\basesrv.dll
15:16:53.0873 6124 [ 008F51AE989C3DF1CBAF8B39DC423CCC ] C:\Windows\system32\winsrv.dll
15:16:53.0888 6124 [ 008F51AE989C3DF1CBAF8B39DC423CCC ] C:\Windows\system32\winsrv.dll
15:16:53.0920 6124 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
15:16:53.0935 6124 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
15:16:53.0951 6124 [Global] - ok
15:16:53.0951 6124 ================ Scan MBR ==================================
15:16:53.0966 6124 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
15:16:54.0450 6124 \Device\Harddisk0\DR0 - ok
15:16:54.0450 6124 ================ Scan VBR ==================================
15:16:54.0450 6124 [ D22E15A9F4A7311EABEF782F7A0A681A ] \Device\Harddisk0\DR0\Partition1
15:16:54.0450 6124 \Device\Harddisk0\DR0\Partition1 - ok
15:16:54.0512 6124 [ FA18A167E385B7C3D3A2C6C8AF0378DB ] \Device\Harddisk0\DR0\Partition2
15:16:54.0512 6124 \Device\Harddisk0\DR0\Partition2 - ok
15:16:54.0512 6124 ============================================================
15:16:54.0512 6124 Scan finished
15:16:54.0512 6124 ============================================================
15:16:54.0528 0632 Detected object count: 0
15:16:54.0528 0632 Actual detected object count: 0

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 14 zář 2012 15:41

ComboFix 12-09-14.01 - Luciasheq 14.09.2012 15:24:02.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2043.1260 [GMT 2:00]
Spuštěný z: c:\users\Luciasheq\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Předchozí spuštění -------
.
c:\users\Luciasheq\AppData\Local\TempDIR
c:\windows\pkunzip.pif
c:\windows\pkzip.pif
c:\windows\security\Database\tmp.edb
.
-- Předchozí spuštění --
.
c:\windows\system32\userinit.exe . . . je infikován!!
.
--------
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_COMSysApp
-------\Service_COMSysApp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-14 do 2012-09-14 )))))))))))))))))))))))))))))))
.
.
2012-09-14 13:32 . 2012-09-14 13:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-13 18:24 . 2012-09-13 18:24 388096 ----a-r- c:\users\Luciasheq\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-09-13 17:14 . 2012-09-14 13:35 -------- d-----w- c:\users\Luciasheq\AppData\Local\temp
2012-09-13 16:45 . 2012-09-13 16:45 -------- d-----w- C:\Local Disk D_91320121845
2012-09-13 14:12 . 2012-09-14 13:26 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9FCADB8F-B648-443B-9E26-442DF6449CED}\offreg.dll
2012-09-13 14:01 . 2012-05-17 15:36 2468520 ----a-w- c:\windows\system32\BootMan.exe
2012-09-13 14:01 . 2011-07-29 11:54 19840 ----a-w- c:\windows\system32\EuEpmGdi.dll
2012-09-13 14:01 . 2011-07-29 11:54 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2012-09-13 14:01 . 2011-07-29 11:54 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys
2012-09-13 14:01 . 2011-07-29 11:54 14216 ----a-w- c:\windows\system32\epmntdrv.sys
2012-09-13 14:01 . 2012-09-13 14:01 -------- d-----w- c:\program files\EaseUS
2012-09-13 13:20 . 2012-09-13 13:20 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2012-09-13 13:18 . 2011-10-19 20:15 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-09-13 13:05 . 2012-09-13 13:05 -------- d-----w- c:\programdata\IObit
2012-09-13 13:05 . 2012-09-13 18:16 -------- d-----w- c:\users\Luciasheq\AppData\Roaming\IObit
2012-09-13 13:05 . 2012-09-13 18:16 -------- d-----w- c:\program files\IObit
2012-09-13 12:56 . 2012-09-13 12:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-13 12:56 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-12 19:05 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{9FCADB8F-B648-443B-9E26-442DF6449CED}\mpengine.dll
2012-09-12 19:05 . 2012-08-02 17:05 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-08-17 16:25 . 2012-07-06 19:31 393216 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-08-15 19:31 . 2012-05-05 07:44 400896 ----a-w- c:\windows\system32\srcore.dll
2012-08-15 19:31 . 2012-07-18 17:10 2344448 ----a-w- c:\windows\system32\win32k.sys
2012-08-15 19:31 . 2012-02-11 05:44 492032 ----a-w- c:\windows\system32\win32spl.dll
2012-08-15 19:31 . 2012-02-11 05:41 316928 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-15 19:30 . 2012-07-04 21:23 41472 ----a-w- c:\windows\system32\browcli.dll
2012-08-15 19:30 . 2012-07-04 21:23 102912 ----a-w- c:\windows\system32\browser.dll
2012-08-15 19:30 . 2012-05-14 04:37 768512 ----a-w- c:\windows\system32\localspl.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-29 14:48 . 2012-03-16 16:03 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-06-20 14:40 . 2012-03-16 16:03 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2012-05-30 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-02-11 07:58 185856 ----a-w- c:\program files\Get Styles\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-11-12 1647448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-29 1537320]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-02-23 204800]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-09 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2012-07-02 4473728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R2 gupdate;Služba Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R2 SkypeUpdate;Skype Updater; [x]
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [x]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [x]
R3 gupdatem;Služba Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 MozillaMaintenance;Mozilla Maintenance Service; [x]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [x]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [x]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files\Guard-ICQ\GuardICQ.exe [x]
S2 ICQ Service;ICQ Service;c:\progra~1\ICQ6TO~1\ICQSER~1.EXE [x]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - FSUSBEXDISK
.
Obsah adresáře 'Naplánované úlohy'
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-02-22 12:10]
.
2012-09-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-02-22 12:10]
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 82.100.3.1 62.240.162.158
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
HKLM-Run-NPSStartup - (no file)
AddRemove-rajče.net_is1 - d:\program files\rajce\unins000.exe
AddRemove-{4817189D-1785-4627-A33C-39FD90919300} - d:\program files\EA GAMES\The Sims 2 Mazlíčci\EAUninstall.exe
AddRemove-{5C648FDB-0138-4619-B66E-230EF53E8E2C} - d:\program files\EA GAMES\The Sims 2 Pro Teenagery Kolekce\EAUninstall.exe
AddRemove-{64EEA791-0271-4B53-00AC-2BF05F5FBEF6} - d:\program files\Electronic Arts\The Sims Příběhy trosečníků\EAUninstall.exe
AddRemove-{6522C636-B04C-4333-9BEB-9E0C0B6350D6} - d:\program files\EA GAMES\The Sims 2 Koupelny a kuchyně Interiérový design Kolekce\EAUninstall.exe
AddRemove-{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0} - d:\program files\EA GAMES\The Sims 2 Pro rodinnou zábavu - Kolekce\EAUninstall.exe
AddRemove-{6E17F9751-F056-4335-B718-8AF1B1092AFB} - d:\program files\EA GAMES\The Sims 2 IKEA® Domov Kolekce\EAUninstall.exe
AddRemove-{6E7DD182-9FC6-4651-0095-2E666CC6AF35} - d:\program files\EA GAMES\The Sims 2\EAUninstall.exe
AddRemove-{7B3577F5-1D82-4C9B-008B-69D026FD8BCA} - d:\program files\EA GAMES\The Sims 2 Ve světě podnikání\EAUninstall.exe
AddRemove-{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75} - d:\program files\EA GAMES\The Sims 2 H&M® Móda Kolekce\EAUninstall.exe
AddRemove-{87F6C83D-F949-4d14-B5CB-DC8C75F8932D} - d:\program files\EA GAMES\The Sims 2 Volný čas\EAUninstall.exe
AddRemove-{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2} - d:\program files\EA GAMES\The Sims 2 University\EAUninstall.exe
AddRemove-{9CDBC303-3EED-40b0-8E41-A7C65AA96C26} - d:\program files\EA GAMES\The Sims 2 Pro luxusní život - Kolekce\EAUninstall.exe
AddRemove-{B6F5B704-06D3-4687-90F3-6195304AD755} - d:\program files\EA GAMES\The Sims 2 Život v bytě\EAUninstall.exe
AddRemove-{DA932D71-E52A-43D5-009E-395A1AEC1474} - d:\program files\Electronic Arts\The Sims Životní Příběhy\EAUninstall.exe
AddRemove-{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06} - d:\program files\EA GAMES\The Sims 2 Roční období\EAUninstall.exe
AddRemove-{EAA38532-7AD0-4f78-918A-4F4F02096ECE} - d:\program files\EA GAMES\The Sims 2 Pojďme slavit! Kolekce\EAUninstall.exe
AddRemove-{F248ADFA-64E0-4b03-8A83-059078BED6A0} - d:\program files\EA GAMES\The Sims 2 Šťastnou cestu\EAUninstall.exe
AddRemove-{F7529650-B9DB-481B-0089-A2AC3C2821C1} - d:\program files\EA GAMES\The Sims 2 Noční život\EAUninstall.exe
AddRemove-{Fantom - Zlocin v Benatkach - Sberatelska edice}_is1 - d:\program files\Fantom - Zlocin v Benatkach - Sberatelska edice\unins000.exe
AddRemove-{Mesto hrichu}_is1 - d:\program files\Mesto hrichu\unins000.exe
AddRemove-{Odysseus - Dlouha cesta domu}_is1 - d:\program files\Odysseus - Dlouha cesta domu\unins000.exe
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\atieclxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\conhost.exe
c:\windows\system32\sppsvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2012-09-14 15:39:08 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-14 13:39
.
Před spuštěním: Volných bajtů: 204 118 880 256
Po spuštění: Volných bajtů: 203 949 780 992
.
- - End Of File - - 99D397E877B8937A716506E908FECA89

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43298
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: USERINIT.exe nakažen

Příspěvekod jaro3 » 15 zář 2012 10:06

Celá rodina zavirovaná... :D

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:

Kód: Vybrat vše

ClearJavaCache::

KillAll::
Restore::
c:\windows\system32\userinit.exe

File::
c:\program files\Google\Update\GoogleUpdate.exe

Folder::
c:\program files\Google\Update

Driver::
gupdate
SkypeUpdate
gupdatem

RegNull::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]

RegLock::
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]



Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upusť.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu + nový log z HJT

Upozornění : Může se stát, že po aplikaci Combofixu a restartu počítače, Windows nenaběhnou , nebo nenajede plocha , budou problémy s připojením, pak znovu restartuj počítač, pokud to nepomůže , po restartu mačkej klávesu F8 a pak zvol poslední známou funkční konfiguraci. , či použij bod obnovy.

Stáhni si aswMBR
na svojí plochu. Uzavři všechna okna , programy a prohlížeče. Poklepej na aswMBR.exe. Pokud se objeví hláška o možnosti stáhnutí databáze Avastu , klikni na NE. Poté klikni na „Scan“ . Po skenu klikni na „Save Log“ a ulož si log na plochu .Zkopíruj sem celý obsah toho logu. Pak klikni na „Exit“ k zavření programu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 15 zář 2012 23:50

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:49:50, on 15.9.2012
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v9.00 (9.00.8112.16448)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\IObit\Advanced SystemCare 5\AutoSweep.exe
C:\Windows\system32\conhost.exe
C:\ComboFix\PEV.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Get Styles\enlbrdr.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [IObit Malware Fighter] "C:\Program Files\IObit\IObit Malware Fighter\IMF.exe" /autostart
O4 - HKCU\..\Run: [Advanced SystemCare 5] "C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe" /AutoStart
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Advanced SystemCare Service 5 (AdvancedSystemCareService5) - IObit - C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Guard.Mail.ru - Unknown owner - C:\Program Files\Guard-ICQ\GuardICQ.exe
O23 - Service: ICQ Service - Unknown owner - C:\PROGRA~1\ICQ6TO~1\ICQSER~1.EXE
O23 - Service: IMF Service (IMFservice) - IObit - C:\Program Files\IObit\IObit Malware Fighter\IMFsrv.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 4705 bytes

ComboFix 12-09-14.01 - Luciasheq 15.09.2012 23:32:47.3.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2043.1254 [GMT 2:00]
Spuštěný z: c:\users\Luciasheq\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Luciasheq\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
FILE ::
"c:\program files\Google\Update\GoogleUpdate.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Google\Update
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler.exe
c:\program files\Google\Update\1.3.21.115\GoogleCrashHandler64.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdate.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateBroker.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateHelper.msi
c:\program files\Google\Update\1.3.21.115\GoogleUpdateOnDemand.exe
c:\program files\Google\Update\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\1.3.21.115\goopdate.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_am.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ar.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bg.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_bn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ca.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_cs.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_da.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_de.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_el.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en-GB.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_en.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es-419.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_es.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_et.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fa.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fil.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_fr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_gu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_hu.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_id.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_is.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_it.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_iw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ja.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_kn.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ko.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lt.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_lv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ml.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_mr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ms.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_nl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_no.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-BR.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_pt-PT.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ro.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ru.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sl.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sv.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_sw.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ta.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_te.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_th.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_tr.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_uk.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_ur.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_vi.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-CN.dll
c:\program files\Google\Update\1.3.21.115\goopdateres_zh-TW.dll
c:\program files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
c:\program files\Google\Update\1.3.21.115\psmachine.dll
c:\program files\Google\Update\1.3.21.115\psuser.dll
c:\program files\Google\Update\Download\{430FD4D0-B729-4F61-AA34-91526481799D}\1.3.21.115\GoogleUpdateSetup.exe
c:\program files\Google\Update\Download\{4DC8B4CA-1BDA-483E-B5FA-D3C12E15B62D}\21.0.1180.89\21.0.1180.89_21.0.1180.83_chrome_updater.exe
c:\program files\Google\Update\GoogleUpdate.exe
.
Nakažená kopie c:\windows\system32\userinit.exe byla nalezena a vyléčena.
Obnovena kopie z - c:\windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_gupdate
-------\Service_gupdatem
-------\Service_SkypeUpdate
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-15 do 2012-09-15 )))))))))))))))))))))))))))))))
.
.
2012-09-15 21:42 . 2012-09-15 21:42 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6B8A6F2-F825-48D5-BD0B-74C94F96A524}\offreg.dll
2012-09-15 21:41 . 2012-09-15 21:45 -------- d-----w- c:\users\Luciasheq\AppData\Local\temp
2012-09-15 21:41 . 2012-09-15 21:41 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-14 18:08 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6B8A6F2-F825-48D5-BD0B-74C94F96A524}\mpengine.dll
2012-09-13 18:24 . 2012-09-13 18:24 388096 ----a-r- c:\users\Luciasheq\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-09-13 16:45 . 2012-09-13 16:45 -------- d-----w- C:\Local Disk D_91320121845
2012-09-13 14:01 . 2012-05-17 15:36 2468520 ----a-w- c:\windows\system32\BootMan.exe
2012-09-13 14:01 . 2011-07-29 11:54 19840 ----a-w- c:\windows\system32\EuEpmGdi.dll
2012-09-13 14:01 . 2011-07-29 11:54 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2012-09-13 14:01 . 2011-07-29 11:54 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys
2012-09-13 14:01 . 2011-07-29 11:54 14216 ----a-w- c:\windows\system32\epmntdrv.sys
2012-09-13 14:01 . 2012-09-13 14:01 -------- d-----w- c:\program files\EaseUS
2012-09-13 13:20 . 2012-09-13 13:20 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2012-09-13 13:18 . 2011-10-19 20:15 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-09-13 13:05 . 2012-09-13 13:05 -------- d-----w- c:\programdata\IObit
2012-09-13 13:05 . 2012-09-13 18:16 -------- d-----w- c:\users\Luciasheq\AppData\Roaming\IObit
2012-09-13 13:05 . 2012-09-13 18:16 -------- d-----w- c:\program files\IObit
2012-09-13 12:56 . 2012-09-13 12:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-13 12:56 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-12 19:05 . 2012-08-02 17:05 490496 ----a-w- c:\windows\system32\d3d10level9.dll
2012-08-17 16:25 . 2012-07-06 19:31 393216 ----a-w- c:\windows\system32\drivers\bthport.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-14 14:09 . 2012-03-10 10:48 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-09-14 14:09 . 2012-03-10 10:48 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-07-18 17:10 . 2012-08-15 19:31 2344448 ----a-w- c:\windows\system32\win32k.sys
2012-07-04 21:23 . 2012-08-15 19:30 41472 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:23 . 2012-08-15 19:30 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 14:48 . 2012-03-16 16:03 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-06-20 14:40 . 2012-03-16 16:03 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2012-05-30 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-02-11 07:58 185856 ----a-w- c:\program files\Get Styles\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-11-12 1647448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-29 1537320]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-02-23 204800]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-09 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2012-07-02 4473728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [x]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service; [x]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [x]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [x]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files\Guard-ICQ\GuardICQ.exe [x]
S2 ICQ Service;ICQ Service;c:\progra~1\ICQ6TO~1\ICQSER~1.EXE [x]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
Obsah adresáře 'Naplánované úlohy'
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 82.100.3.1 62.240.162.158
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\atieclxx.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\IObit\Advanced SystemCare 5\AutoSweep.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2012-09-15 23:48:42 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-15 21:48
ComboFix2.txt 2012-09-14 13:39
.
Před spuštěním: Volných bajtů: 202 124 431 360
Po spuštění: Volných bajtů: 202 369 671 168
.
- - End Of File - - 4C92C53D72FAE60AA6D87049AF9858B1

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 15 zář 2012 23:59

Jn jsme to ale rodinka :D


aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
Run date: 2012-09-15 23:52:42
-----------------------------
23:52:42.355 OS Version: Windows 6.1.7600
23:52:42.355 Number of processors: 2 586 0x170A
23:52:42.355 ComputerName: LUCIASHEQ-PC UserName: Luciasheq
23:52:43.665 Initialize success
23:52:43.805 AVAST engine defs: 12091500
23:52:47.612 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
23:52:47.612 Disk 0 Vendor: Hitachi_HTS545050B9A300 PB4OC60F Size: 476940MB BusType: 3
23:52:47.674 Disk 0 MBR read successfully
23:52:47.674 Disk 0 MBR scan
23:52:47.674 Disk 0 Windows 7 default MBR code
23:52:47.690 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 220007 MB offset 63
23:52:47.721 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 256930 MB offset 450575061
23:52:47.752 Disk 0 scanning sectors +976768065
23:52:47.830 Disk 0 scanning C:\Windows\system32\drivers
23:52:58.454 Service scanning
23:53:24.178 Modules scanning
23:53:33.242 Module: C:\Windows\System32\user32.dll **SUSPICIOUS**
23:53:37.672 Disk 0 trace - called modules:
23:53:37.688 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x84e5b1e8]<<
23:53:37.703 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85c8e700]
23:53:37.703 3 CLASSPNP.SYS[8931259e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85b975e8]
23:53:37.703 \Driver\atapi[0x857a0410] -> IRP_MJ_CREATE -> 0x84e5b1e8
23:53:38.515 AVAST engine scan C:\Windows
23:53:40.402 AVAST engine scan C:\Windows\system32
23:55:28.749 AVAST engine scan C:\Windows\system32\drivers
23:55:37.752 AVAST engine scan C:\Users\Luciasheq
23:57:56.514 AVAST engine scan C:\ProgramData
23:58:15.094 Scan finished successfully
23:58:50.162 Disk 0 MBR has been saved successfully to "C:\Users\Luciasheq\Documents\MBR.dat"
23:58:50.178 The log file has been saved successfully to "C:\Users\Luciasheq\Documents\aswMBR.txt"

Uživatelský avatar
memphisto
Guru Level 13
Guru Level 13
Příspěvky: 21113
Registrován: září 06
Bydliště: Zlín - České Budějovice
Pohlaví: Muž
Stav:
Offline

Re: USERINIT.exe nakažen

Příspěvekod memphisto » 16 zář 2012 12:05

Otevři si Poznámkový blok (Start -> Spustit... a napiš do okna Notepad a dej Ok.
Zkopíruj do něj následující celý text označený zeleně:
Poznámka: Nepoužij k označení skriptu funkci VYBRAT VŠE

Kód: Vybrat vše

KillAll::
DirLook::
C:\Local Disk D_91320121845

Driver::
ICQ Service

Folder::
c:\progra~1\ICQ6TO~1

Zvol možnost Soubor -> Uložit jako... a nastav tyto parametry:
Název souboru: zde napiš: CFScript.txt
Uložit jako typ: tak tam vyber Všechny soubory
Ulož soubor na plochu.
Ukonči všechna aktivní okna.

Uchop myší vytvořený skript CFScript.txt, přemísti ho nad stažený program ComboFix.exe a když se oba soubory překryjí, skript upus.
- Automaticky se spustí ComboFix
- Vlož sem log, který vyběhne v závěru čistícího procesu
PRAVIDLA PC-HELP.CZ, PRAVIDLA sekce HijackThis, HijackThis návod, Memtest, CCleaner
Logy z programu HijackThis neposílejte prosím přes SZ, ale vkládejte je do patřičné sekce. Děkuji

Uživatelský avatar
autoprd
Level 4.5
Level 4.5
Příspěvky: 1715
Registrován: únor 09
Bydliště: ▼▲☺U Pc ☺▼▲
Pohlaví: Muž
Stav:
Offline
Kontakt:

Re: USERINIT.exe nakažen

Příspěvekod autoprd » 16 zář 2012 21:09

ComboFix 12-09-14.01 - Luciasheq 16.09.2012 20:51:22.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1250.420.1029.18.2043.1348 [GMT 2:00]
Spuštěný z: c:\users\Luciasheq\Desktop\ComboFix.exe
Použité ovládací přepínače :: c:\users\Luciasheq\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: IObit Malware Fighter *Disabled/Updated* {A751AC20-3B48-5237-898A-78C4436BB78D}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Vytvořen nový Bod Obnovení
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\progra~1\ICQ6TO~1
c:\progra~1\ICQ6TO~1\config.xml
c:\progra~1\ICQ6TO~1\Icons.bmp
c:\progra~1\ICQ6TO~1\ICQ Service.exe
c:\progra~1\ICQ6TO~1\icq6Toolbar.ico
c:\progra~1\ICQ6TO~1\ICQToolBar.dll
c:\progra~1\ICQ6TO~1\ICQUnToolbar.exe
c:\progra~1\ICQ6TO~1\logo_small.gif
c:\progra~1\ICQ6TO~1\ServiceStarter.exe
c:\progra~1\ICQ6TO~1\short.wav
c:\progra~1\ICQ6TO~1\Version.txt
c:\progra~1\ICQ6TO~1\voucher.bmp
c:\progra~1\ICQ6TO~1\voucher2.bmp
.
.
((((((((((((((((((((((((((((((((((((((( Ovladače/Služby )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_ICQ Service
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2012-08-16 do 2012-09-16 )))))))))))))))))))))))))))))))
.
.
2012-09-16 19:00 . 2012-09-16 19:04 -------- d-----w- c:\users\Luciasheq\AppData\Local\temp
2012-09-16 19:00 . 2012-09-16 19:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-09-15 21:42 . 2012-09-15 21:42 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6B8A6F2-F825-48D5-BD0B-74C94F96A524}\offreg.dll
2012-09-14 18:08 . 2012-08-23 07:15 7022536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{E6B8A6F2-F825-48D5-BD0B-74C94F96A524}\mpengine.dll
2012-09-13 18:24 . 2012-09-13 18:24 388096 ----a-r- c:\users\Luciasheq\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-09-13 16:45 . 2012-09-13 16:45 -------- d-----w- C:\Local Disk D_91320121845
2012-09-13 14:01 . 2012-05-17 15:36 2468520 ----a-w- c:\windows\system32\BootMan.exe
2012-09-13 14:01 . 2011-07-29 11:54 19840 ----a-w- c:\windows\system32\EuEpmGdi.dll
2012-09-13 14:01 . 2011-07-29 11:54 86408 ----a-w- c:\windows\system32\setupempdrv03.exe
2012-09-13 14:01 . 2011-07-29 11:54 8456 ----a-w- c:\windows\system32\EuGdiDrv.sys
2012-09-13 14:01 . 2011-07-29 11:54 14216 ----a-w- c:\windows\system32\epmntdrv.sys
2012-09-13 14:01 . 2012-09-13 14:01 -------- d-----w- c:\program files\EaseUS
2012-09-13 13:20 . 2012-09-13 13:20 12800 ----a-w- c:\windows\system32\drivers\sffp_sd.sys
2012-09-13 13:18 . 2011-10-19 20:15 20312 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-09-13 13:05 . 2012-09-13 13:05 -------- d-----w- c:\programdata\IObit
2012-09-13 13:05 . 2012-09-13 18:16 -------- d-----w- c:\users\Luciasheq\AppData\Roaming\IObit
2012-09-13 13:05 . 2012-09-13 18:16 -------- d-----w- c:\program files\IObit
2012-09-13 12:56 . 2012-09-13 12:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-09-13 12:56 . 2012-09-07 15:04 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-09-12 19:05 . 2012-08-02 17:05 490496 ----a-w- c:\windows\system32\d3d10level9.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-14 14:09 . 2012-03-10 10:48 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2012-09-14 14:09 . 2012-03-10 10:48 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2012-07-18 17:10 . 2012-08-15 19:31 2344448 ----a-w- c:\windows\system32\win32k.sys
2012-07-06 19:31 . 2012-08-17 16:25 393216 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-07-04 21:23 . 2012-08-15 19:30 41472 ----a-w- c:\windows\system32\browcli.dll
2012-07-04 21:23 . 2012-08-15 19:30 102912 ----a-w- c:\windows\system32\browser.dll
2012-06-29 14:48 . 2012-03-16 16:03 483952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2012-06-29 00:16 . 2012-08-17 16:24 1800704 ----a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-17 16:24 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-17 16:24 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-17 16:24 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-17 16:24 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-06-20 14:40 . 2012-03-16 16:03 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Local Disk D_91320121845 ----
.
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2012-05-30 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
[7] 2010-11-20 . F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 . 811520 . . [6.1.7601.17514] . . c:\windows\SoftwareDistribution\Download\18e2c83e42cc8f0cc17b5dbfaf982690\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]
2010-02-11 07:58 185856 ----a-w- c:\program files\Get Styles\enlbrdr.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-11-28 18:01 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 5"="c:\program files\IObit\Advanced SystemCare 5\ASCTray.exe" [2011-11-12 1647448]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-06-29 1537320]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2009-02-23 204800]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-11-28 3744552]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-09 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-20 59240]
"IObit Malware Fighter"="c:\program files\IObit\IObit Malware Fighter\IMF.exe" [2012-07-02 4473728]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [x]
R3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [x]
R3 FileMonitor;FileMonitor;c:\program files\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys [x]
R3 MozillaMaintenance;Mozilla Maintenance Service; [x]
R3 RegFilter;RegFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\regfilter.sys [x]
R3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\DRIVERS\ss_bbus.sys [x]
R3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\DRIVERS\ss_bmdfl.sys [x]
R3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\DRIVERS\ss_bmdm.sys [x]
R3 UrlFilter;UrlFilter;c:\program files\IObit\IObit Malware Fighter\drivers\win7_x86\UrlFilter.sys [x]
R3 WatAdminSvc;Služba Technologie aktivace Windows;c:\windows\system32\Wat\WatAdminSvc.exe [x]
S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdvancedSystemCareService5;Advanced SystemCare Service 5;c:\program files\IObit\Advanced SystemCare 5\ASCService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [x]
S2 Guard.Mail.ru;Guard.Mail.ru;c:\program files\Guard-ICQ\GuardICQ.exe [x]
S2 IMFservice;IMF Service;c:\program files\IObit\IObit Malware Fighter\IMFsrv.exe [x]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [x]
S3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [x]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Ostatní služby/ovladače v paměti ---
.
*NewlyCreated* - FSUSBEXDISK
.
.
------- Doplňkový sken -------
.
IE: E&xportovat do aplikace Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 82.100.3.1 62.240.162.158
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
AddRemove-ICQToolbar - c:\program files\ICQ6Toolbar\ICQUnToolbar.exe
.
.
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\AUDIODG.EXE
c:\windows\system32\atieclxx.exe
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\taskhost.exe
c:\program files\IObit\Advanced SystemCare 5\AutoSweep.exe
c:\program files\LSI SoftModem\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Celkový čas: 2012-09-16 21:07:36 - počítač byl restartován
ComboFix-quarantined-files.txt 2012-09-16 19:07
ComboFix2.txt 2012-09-15 21:48
ComboFix3.txt 2012-09-14 13:39
.
Před spuštěním: Volných bajtů: 202 174 189 568
Po spuštění: Volných bajtů: 202 419 195 904
.
- - End Of File - - 6EC8E9172BD90A639AF84FAAD4DB1330


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 78 hostů